Patentable/Patents/US-9787711
US-9787711

Enabling custom countermeasures from a security device

PublishedOctober 10, 2017
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

A security device may receive information identifying a set of conditions for providing countermeasure code to a client device. The security device may receive information identifying an action to be performed when the countermeasure code is executed by the client device, and may determine the countermeasure code to be provided to the client device when the set of conditions is satisfied. The security device may receive a request from the client device, and may determine a response to the request. The response may include response code for serving content of a web page to the client device. The security device may determine that the set of conditions has been satisfied, and may insert the countermeasure code into the response code. The security device may provide the response code and the countermeasure code to the client device, and the countermeasure code may cause the client device to perform the action.

Patent Claims
20 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A security device, comprising: one or more processors; and a non-transitory computer-readable medium storing instructions that, when executed by the one or more processors, cause the one or more processors to: determine countermeasure code to be injected into a response provided to a first device; receive a request from the first device, the request being intended for a second device; receive, from the second device, the response to the request; inject the countermeasure code into the response; provide the response, including the countermeasure code, to the first device; determine client device information based on providing the response to the first device, the client device information identifying at least one of: a quantity of times that the countermeasure code or other countermeasure code was provided to the first device, a quantity of attacks associated with the first device, a profile associated with the first device, an action performed by the first device based on the countermeasure code, an indication of whether the countermeasure code was executed by the first device, a quantity of times that the first device has executed the countermeasure code or the other countermeasure code, or information captured from the first device based on execution of the countermeasure code; and omit the countermeasure code from a subsequent response provided to the first device based on the client device information.

2

2. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes information that identifies an application executing on the first device.

3

3. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes information that identifies a file accessible by the first device.

4

4. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes information that identifies contents of a file accessible by the first device.

5

5. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes information that identifies a configuration associated with the first device.

6

6. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes a screenshot of information provided for display by the first device.

7

7. The security device of claim 1 , where the client device information identifies the information captured from the first device based on execution of the countermeasure code, and where the information captured from the first device includes an image captured using a camera associated with the first device.

8

8. A non-transitory computer-readable medium storing instructions, the instructions comprising one or more instructions that, when executed by one or more processors, cause the one or more processors to: determine countermeasure code to be inserted into a response provided to a first device; receive a request from the first device, the request being intended for a second device; receive, from the second device, the response to the request; insert the countermeasure code into the response; provide the response, including the countermeasure code, to the first device; determine client device information based on providing the response to the first device, the client device information identifying at least one of: a quantity of times that the countermeasure code or other countermeasure code was provided to the first device, a quantity of attacks associated with the first device, a profile associated with the first device, an action performed by the first device based on the countermeasure code, an indication of whether the countermeasure code was executed by the first device, a quantity of times that the first device has executed the countermeasure code or the other countermeasure code, or information received from the first device based on execution of the countermeasure code; and omit the countermeasure code from a subsequent response provided to the first device based on the client device information.

9

9. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to determine the countermeasure code, cause the one or more processors to: randomize a characteristic of the countermeasure code; and determine the countermeasure code based on randomizing the characteristic of the countermeasure code.

10

10. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to determine the countermeasure code, cause the one or more processors to: randomize a variable name included in the countermeasure code; and determine the countermeasure code based on randomizing the variable name included in the countermeasure code.

11

11. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to determine the countermeasure code, cause the one or more processors to: randomize an order of code segments included in the countermeasure code; and determine the countermeasure code based on randomizing the order of the code segments included in the countermeasure code.

12

12. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to determine the countermeasure code, cause the one or more processors to: obfuscate the countermeasure code by including at least one code segment, in the countermeasure code, that does not perform any action when executed; and determine the countermeasure code based on obfuscating the countermeasure code.

13

13. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to determine the countermeasure code, cause the one or more processors to: obfuscate the countermeasure code by encrypting at least one code segment included in the countermeasure code; and determine the countermeasure code based on obfuscating the countermeasure code.

14

14. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to insert the countermeasure code into the response, cause the one or more processors to: randomize a location of the countermeasure code within the response; and insert the countermeasure code into the response based on randomizing the location of the countermeasure code within the response.

15

15. A method, comprising: determining, by a security device, countermeasure code to be injected into a response provided to a client device; receiving, by the security device, a request from the client device, the request being intended for a server device; receiving, by the security device and from the server device, the response to the request; injecting, by the security device, the countermeasure code into the response; providing, by the security device, the response, including the countermeasure code, to the client device; determining, by the security device, client device information based on providing the response to the client device, the client device information identifying at least one of: a quantity of times that the countermeasure code or other countermeasure code was provided to the client device, a quantity of attacks associated with the client device, a profile associated with the client device, an action performed by the client device based on the countermeasure code, an indication of whether the countermeasure code was executed by the client device, a quantity of times that the client device has executed the countermeasure code or the other countermeasure code, or information received from the client device based on execution of the countermeasure code; and omitting, by the security device, the countermeasure code from a subsequent response provided to the client device based on the client device information.

16

16. The method of claim 15 , where omitting the countermeasure code from the subsequent response comprises: providing the subsequent response without including any countermeasure code in the subsequent response.

17

17. The method of claim 15 , where omitting the countermeasure code from the subsequent response comprises: providing the subsequent response with a different countermeasure code that is different from the countermeasure code.

18

18. The method of claim 15 , where the client device information identifies the action performed by the client device based on the countermeasure code, and where the action performed by the client device is based on user input provided to the client device in association with the countermeasure code.

19

19. The method of claim 15 , where the client device information identifies the profile associated with the client device, and where the profile includes a user profile of a user associated with the client device.

20

20. The method of claim 15 , where determining the client device information comprises: determining the client device information via an application programming interface accessed by the client device based on execution of the countermeasure code.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

October 30, 2015

Publication Date

October 10, 2017

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Enabling custom countermeasures from a security device” (US-9787711). https://patentable.app/patents/US-9787711

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.